AWS Serverless Eda
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/core-skills/aws-auth .claude/skills/aws-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-auth" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-auth into .claude/skills/aws-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/core-skills/aws-auth .agents/skills/aws-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-auth" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-auth into .agents/skills/aws-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/core-skills/aws-auth .cursor/skills/aws-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-auth" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-auth into .cursor/skills/aws-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path skills/core-skills/aws-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/core-skills/aws-auth .gemini/skills/aws-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-auth" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-auth into .gemini/skills/aws-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws aws-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/core-skills/aws-auth .github/skills/aws-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-auth" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-auth into .github/skills/aws-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/core-skills/aws-auth .opencode/skills/aws-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-auth" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-auth into .opencode/skills/aws-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-authAdds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries.
AWS Auth is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries. Covers sign-up/sign-in flows and the login page (Cognito-hosted UI / managed login), MFA, password policies, OAuth 2.0 / OIDC flows (auth-code + PKCE, client credentials), social/SAML federation, tokens (ID/access/refresh, rotation, revocation, storage), Cognito Lambda triggers, identity pools (temp AWS creds), and gating API Gateway (or ALB) routes to signed-in users via…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `references/api-authorization.md`, `references/identity-pools.md` and `references/lambda-triggers.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect, Authentication and Microservices. It works with Amazon Web Services, AWS Lambda and Amazon DynamoDB. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comgithub.comaws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Auth loads about 3.4k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 1,393 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 1,393 words, ~3,438 tokens.
.claude/skills/aws-auth/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Application-level user authentication and authorization with Amazon Cognito and the Amplify client auth libraries. Verify specific limits, quotas, and exact API shapes against official AWS documentation when precision matters; trust the docs over memory when they conflict.
Recommended: The AWS MCP server provides streamlined access to the AWS APIs used in this skill (Cognito user pool/app client/identity pool setup, API Gateway authorizers). If it is unavailable, the AWS CLI commands shown throughout work directly — the skill has no hard dependency on MCP.
When NOT to use: Amplify Gen2 backend code (defineAuth, amplify/auth.ts, npx ampx); IAM
policy/role/trust-policy authoring, STS, or IAM Identity Center console SSO; API Gateway
route/integration setup or Lambda function implementation (this skill covers only the Cognito/JWT
authorizer configuration and the purpose of Cognito Lambda triggers).
These are different services that are frequently confused. Most apps need a user pool; add an identity pool only if the client must call AWS services directly.
| You need... | Use | Why |
|---|---|---|
| Sign-up / sign-in, user directory, issue JWTs | User pool | It authenticates users and is an OIDC IdP |
| The signed-in client to call S3/DynamoDB/etc. directly with AWS credentials | Identity pool | It exchanges a token for temporary AWS credentials via STS |
| Both (sign in, then hit AWS resources from the browser/app) | User pool → identity pool | Identity pool trusts the user pool as its IdP |
If your app only calls your own backend/API, you do not need an identity pool — send the user pool token to your API. See identity-pools.md.
update-user-pool-client and set-identity-pool-roles are FULL REPLACE, not partial updates: Any field you omit is reset to its default — calling update-user-pool-client with only the fields you want to change silently wipes ExplicitAuthFlows, token validity, EnableTokenRevocation, refresh-token rotation, and read/write attributes; set-identity-pool-roles likewise replaces the whole roles + RoleMappings structure. Always read-modify-write: describe-user-pool-client (or get-identity-pool-roles) first, then re-send every existing field plus your change. In an agent context the wipe is invisible — the call succeeds and only breaks later when a user hits the missing flow. See managed-login-oauth.md and identity-pools.md.
Don't use the implicit grant for new apps: The implicit grant (response_type=token) is legacy and returns tokens in the URL fragment. Use the authorization code grant with PKCE (response_type=code + code_challenge) for SPAs and mobile — public clients, no client secret. See managed-login-oauth.md.
Don't store refresh tokens in localStorage for high-value apps: localStorage is readable by any injected script (XSS). The Amplify client library defaults to localStorage; switch to cookieStorage, keep refresh-token lifetime short, and enable refresh token rotation + token revocation on the app client. See tokens-and-sessions.md.
Access-token claim customization needs a paid feature plan: The pre token generation trigger customizes the ID token on the entry-level plan (V1), but customizing the access token (V2/V3) requires a paid feature plan — check the Cognito feature plans documentation for which plan currently includes this, as plan names and inclusions can change. Don't assume access-token claims work on the entry-level plan. See lambda-triggers.md.
App client secret + SPA = broken auth: A public client (browser/mobile) must have no client secret. If a secret is set, token calls fail unless a SECRET_HASH is sent, which a browser cannot protect. Generate a secret only for confidential (server-side) clients.
Don't bulk admin-confirm-sign-up UNCONFIRMED users: When users are stuck UNCONFIRMED, prefer resend-confirmation-code so each user re-verifies via confirm-sign-up and proves email ownership (the code likely expired or went to spam). admin-confirm-sign-up flips the status instantly but confirms the account without verifying the email — the attribute stays unverified, which is dangerous when email drives password reset or account linking. Reserve it for trusted/migrated accounts. See troubleshooting.md.
| You want to... | Go to |
|---|---|
| Create a user pool, sign-up/sign-in, MFA, password policy, app clients | user-pools.md |
| Add hosted UI / managed login, OAuth flows, social or SAML login, callback URLs, custom domain (ACM in us-east-1) | managed-login-oauth.md |
| Handle ID/access/refresh tokens, rotation, revocation, session termination (global sign-out vs revoke vs disable) | tokens-and-sessions.md |
| Give the client temporary AWS credentials, guest access, role mapping | identity-pools.md |
| Protect an API Gateway API with Cognito tokens (and enforce custom claims in the backend) | api-authorization.md |
Add Cognito login in front of an Application Load Balancer (ALB authenticate-cognito) | api-authorization.md |
| Machine-to-machine (client credentials) auth, resource servers, custom scopes | managed-login-oauth.md |
Create user pool groups and add users to them (cognito:groups, Precedence) | user-pools.md |
| Customize claims, custom auth challenge flows, migrate users, validate sign-up | lambda-triggers.md |
Add passkey / WebAuthn sign-in (USER_AUTH flow, AllowedFirstAuthFactors, WebAuthn enrollment) | passkeys.md |
| Configure threat protection — compromised-credentials block, adaptive auth (risk-based MFA), log delivery to CloudWatch | threat-protection.md |
| Something is broken (redirect, token, MFA, CORS, social login) | troubleshooting.md |
"Add sign-up and login to my React app" → Create a user pool + a public app client (no secret), enable the hosted UI / managed login with the authorization code grant with PKCE, wire the Amplify client library. See user-pools.md and managed-login-oauth.md.
"Add Google / social login" → Register the social IdP on the user pool, map attributes, add the provider to the app client and hosted UI. See managed-login-oauth.md.
"Only authenticated users should call my API" → HTTP API → JWT authorizer; REST API → Cognito user pools authorizer. See api-authorization.md.
"Let the browser upload to S3 after login" → User pool for sign-in, then an identity pool to vend scoped temporary credentials. See identity-pools.md.
| Error/Symptom | Likely Cause | Quick Fix |
|---|---|---|
redirect_mismatch / redirect to wrong URL after login | Callback URL not registered, or scheme/trailing-slash/case differs | Add the exact callback URL (incl. scheme and path) to the app client's Allowed callback URLs |
| Token calls fail with "unable to verify secret hash" | Client secret set on a public (SPA/mobile) client | Recreate the app client with no secret, or send SECRET_HASH from a confidential client |
| Users get 401 from API Gateway with a valid token | Wrong token type or audience/issuer mismatch | HTTP JWT authorizer: issuer https://cognito-idp.{region}.amazonaws.com/{userPoolId}, audience = app client id; send the token the authorizer expects |
| CORS errors calling the hosted UI / token endpoint | Browser calling /oauth2/token cross-origin, or missing CORS on your API | Do the code exchange with PKCE; don't proxy the token endpoint from the browser |
| Social login user "already exists" / attribute conflict | Same email across providers creates separate users | Enable attribute mapping + account linking; treat email as non-unique across IdPs |
Full tables in troubleshooting.md.
cookieStorage over localStorage.iss, aud/client_id, token_use, exp) on every protected request. Use a maintained library such as aws-jwt-verify rather than hand-rolling verification.Content-Security-Policy (restrict script sources to mitigate token-stealing XSS), Strict-Transport-Security (HSTS), X-Frame-Options/frame-ancestors (clickjacking on login pages), and X-Content-Type-Options: nosniff.When you need depth beyond this skill — exact parameter shapes, current limits, edge behaviors — fall back to the authoritative AWS sources rather than guessing. Pointers age much slower than content, so this map stays useful without the skill having to grow.
defineAuth, amplify/auth.ts, npx ampx sandbox).© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in skills/core-skills/aws-auth of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit 188af2f
AWS Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Auth this skillaws/agent-toolkit-for-aws | 2.8k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| AWS Serverless Edazxkane/aws-skills | 367 | 4 repos | ~3.2k | Automated safety check: Pass | MIT | |
| AWS Advisordiegosouzapw/awesome-omni-skills | 159 | — | ~4.3k | Automated safety check: Pass | MIT | |
| AWS Solution Architectalirezarezvani/claude-skills | 28k | 1 repos | ~2.5k | Automated safety check: Pass | MIT | |
| AWS Serverlessdavila7/claude-code-templates | 32k | 8 repos | ~2k | Automated safety check: Pass | MIT | |
| AWS Lambda Durable Functionsawslabs/agent-plugins | 915 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 |
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
diegosouzapw/awesome-omni-skills
AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
alirezarezvani/claude-skills
Design AWS architectures for startups using serverless patterns and IaC templates.
davila7/claude-code-templates
Specialized skill for building production-ready serverless applications on AWS.
awslabs/agent-plugins
Build resilient, long-running, multi-step applications with AWS Lambda durable functions with automatic state persistence, retry logic, and orchestration for long-running executions.
awslabs/agent-plugins
Design, build, deploy, test, and debug serverless applications with AWS Lambda.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Categories
Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries. AWS Auth is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries.
AWS Auth fits situations like: tasks that involve OAuth and OpenID Connect; tasks that involve Authentication; tasks that involve Microservices.
Run `npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a claude-code`. Or copy the skill folder (skills/core-skills/aws-auth in aws/agent-toolkit-for-aws) into .claude/skills/aws-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a codex`. Or copy the skill folder (skills/core-skills/aws-auth in aws/agent-toolkit-for-aws) into .agents/skills/aws-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill aws-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-auth, .gemini/skills/aws-auth, .github/skills/aws-auth and .opencode/skills/aws-auth in your project.
Going by SKILL.md and its folder, AWS Auth needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md names 3 domains. As links in the text: docs.aws.amazon.com, github.com and aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AWS Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 18k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AWS Auth: AWS Serverless Eda (zxkane/aws-skills, 367 stars), AWS Advisor (diegosouzapw/awesome-omni-skills, 159 stars), AWS Solution Architect (alirezarezvani/claude-skills, 28k stars) and AWS Serverless (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.